PT-2015-2757 · Adobe · Coldfusion

Publicado

2015-11-18

·

Atualizado

2020-09-04

·

CVE-2015-8053

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions 10 through 10 before Update 18 Adobe ColdFusion versions 11 through 11 before Update 7
Description The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This occurs due to a lack of protection measures for the web page structure, which can be exploited by a remote attacker to inject arbitrary web scripts or HTML code.
Recommendations For Adobe ColdFusion version 10, apply Update 18 to resolve the issue. For Adobe ColdFusion version 11, apply Update 7 to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12122
CVE-2015-8053
MGASA-2015-0468

Produtos afetados

Coldfusion